CVE-2026-57443: Issdandavis Scbe-Aethermoore
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
SCBE-AETHERMOORE is a geometric AI governance and evaluation framework. Starting in version 4.0.2 and prior to version 4.2.1, the AetherBrowser API server (`scripts/aetherbrowser/api_server.py`) exposes the `POST /api/ops/check-email` endpoint without any authentication. Any remote attacker can call this endpoint and trigger execution of the `email_reader.py` subprocess, which connects to configured ProtonMail or Gmail accounts via IMAP and returns email metadata (sender, subject, body snippet) in the JSON response. The server binds to `0.0.0.0:8100` by default with CORS set to `allow_origins=["*"]`, making it reachable from any network or browser origin. Version 4.2.1 patches the issue.
Affected products
- Issdandavis Scbe-Aethermoore: from 4.0.2, before 4.2.1 (fixed in 4.2.1)
Published 2026-09-25. Last modified 2026-09-30.